CVE-2022-41396: OS Command Injection
Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain multiple command injection vulnerabilities in the function setIPsecTunnelList via the IPsecLocalNet and IPsecRemoteNet parameters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-41396?
CVE-2022-41396 is rated as a high severity vulnerability due to its potential to allow remote code execution via command injection.
How do I fix CVE-2022-41396?
To mitigate CVE-2022-41396, update the Tenda AC1200 Router Model W15Ev2 firmware to the latest version available from the manufacturer.
What product is affected by CVE-2022-41396?
CVE-2022-41396 affects the Tenda AC1200 Router Model W15Ev2 running firmware version 15.11.0.10(1576).
What type of vulnerability is CVE-2022-41396?
CVE-2022-41396 is a command injection vulnerability that can compromise the security of the affected router.
What are the risks associated with CVE-2022-41396?
Exploitation of CVE-2022-41396 could result in unauthorized access and control over the router, allowing attackers to execute arbitrary commands.